5 ms·
>The point of IPv6 was to make the addresses so long they are easy to manage. lol, there is no doubt that had a massive opposite effect. To the point of nearly
by SV_BubbleTime 3mo ago
>The point of IPv6 was to make the addresses so long they are easy to manage.
lol, there is no doubt that had a massive opposite effect. To the point of nearly killing it in terms of willingness to adopt.
- tracker1 3mo agoI know that on my hosted server, I never bothered to set it up, because I didn't know how to properly configure or sub-net it. I know it's skill issue, but really feels significantly more complicated and even harder to understand than NAT even. Not to mention, at home, most of the ads I do see (PiHole) are IPv6 addresses.
- DrewADesign 3mo agoIt seems to have absolutely terrible ergonomics as a technology, in nearly every conceivable way.
- inigyou 3mo agoIt's literally impossible to avoid long addresses being long or short addresses running out. One of those is a worse problem.
- DrewADesign 3mo agoThe length isn’t the only thing that makes the ergonomics suck. The lack of backwards compatibility sucks. The “you don’t have to use NAT anymore” is great theoretically, but it renders a lot of casual network maintainers mental model of network security obsolete without a clear and simple alternative. The shorthand is not intuitive (though it’s not CIDR-level counterintuitive). Really, there’s way too much about working in IPv6 that’s not intuitive with even very solid IPv4 network knowledge. So yeah, having to relearn a bunch of basic network knowledge that worked just fine for decades is a PITA, and I’m 100% positive a design process that focused more on the people that need to configure networks could have yielded a much friendlier, and therefore a much easier to adopt standard.
- redeeman 3mo agoyou fling around words like "network maintainers" quite casually, dont you? :) its really extremely simple, just dont NAT, is that really so hard? just because you dont NAT, doesnt mean you have to let the traffic pass through, that is also an extremely simple concept, no?
- DrewADesign 3mo agoFling it around? There are a shitload of people who maintain networks, like home or small business networks, that aren’t network administrators. Most of those people are not prepared to have their Chinese WiFi cameras, myriad smart appliances, and heck, even home computers easily individually accessible from the internet. It’s an extremely simple concept, no?
- LocalH 3mo agoNAT is good. It's CGNAT that's bad, because that's NAT imposed on subscribers, and not NAT that they control.
- ssl-3 3mo agoLack of NAT doesn't imply lack of firewall, though. And home routers have firewalls that block inbound connections by default -- including with no-NAT IPv6.
- DrewADesign 3mo agoBut lots of people want to do things like open up a few ports for a gaming console. You can obviously do it, but the inside network/outside network/poke a hole/simple ip addresses mental model makes it harder for people to just get frustrated and disable it. Of course absolutely nothing is impossible or more difficult from a technical networking perspective using IPv6. People want to learn as little as humanly possible to solve their problems. If the default easiest path is ‘disable the firewall, and suddenly you can use the LAN pvp mode with your 6th grade classmate’ then you better fucking believe that’s exactly what they’re going to do. The “well it’s not really that complicated” perspective is the main reason adoption of user-facing FOSS is lightyears behind commercial options.
- unethical_ban 3mo agoNo network is "smaller" than /64. All end-networks are /64. Split subnets at four bit chunks. Allocated networks, like to a home or small office, should be /56 or /60. Then you have to think about link-local addresses and privacy addresses, and how to hand out IPv6 and configure DNS: SLAAC vs. DHCPv6 or some combination. I have a rough draft of a beginner document but it's not ready. :)
- zrail 3mo ago(Pedantically) Maximum prefix length of /64 is only required if you want/need SLAAC. If you're assigning static addresses or using DHCPv6 for assignment you can go as small as you want. It's not weird to see /127 for tunnel subnets, for example.
- unethical_ban 3mo agoI didn't want to encourage non-standard behavior, but you are correct. Tunnels are a common use the same way /31s can be used in IPv4. Going smaller than /64 is against best practice and unnecessary. People coming from IPv4 need to understand that trying to be careful with subnet sizing for purposes of preserving space is not a thing in IPv6 below /64. Maybe if a residential user has a /64 from their crappy ISP settings they'd need to do it, but not in a properly configured scenario and certainly not in enterprise.
- inigyou 3mo agoIf you have a network full of static addressed servers, you can go as small as you want. For WiFi networks random devices may connect to, you should just let them pick their own address in a /64 with SLAAC. You may choose to also let servers use SLAAC if you want to, in addition to their static address.
- inigyou 3mo agoHow many /24s does your organisation have? With IPv6, one block is almost always sufficient.
- ErroneousBosh 3mo agoIt's mental that my fairly techy-orientated but otherwise pretty standard UK ISP provides me with a /48 as default. So I have 1.2 million million million million IPv6 addresses available. That ought to be enough, eh?
- kemotep 3mo agoOf course, we could hand all 8 billion people on the planet a thousand /48’s each and still have trillions and trillions to spare.
- inigyou 3mo agoRealistically, allocation is more complicated than that, and there are arguments that the current allocation scheme isn't futureproof enough. But if that happens, there's enough room to change it and still keep all existing allocations working.